Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOLD BURLAP

Also known as: CYBORG SPIDER

Description

GOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as Mespinoza. Pysa is a cross-platform ransomware with known versions written in C++ and Python. As of December 2020, approximately 50 organizations had reportedly been targeted in Pysa ransomware attacks. The operators leverage 'name and shame' tactics to apply additional pressure to victims. As of January 2021, CTU researchers had found no Pysa advertisements on underground forums, which likely indicates that it is not operated as ransomware as a service (RaaS).

Goals & Targeting

Targeted Sectors

Healthcare

AI Analysis

· 1 week ago

Executive Summary

GOLD BURLAP, also known as CYBORG SPIDER, is a financially motivated threat actor group responsible for the development and deployment of the Pysa ransomware (also referred to as Mespinoza). The group primarily targets healthcare organizations, leveraging sophisticated tactics such as 'name and shame' strategies to pressure victims into paying ransoms. While no advertisements for Pysa have been found on underground forums, indicating it is not a ransomware-as-a-service (RaaS) product, the group remains active and poses a significant threat to critical infrastructure.

Goals & Targeting

GOLD BURLAP's primary strategic objective is financial gain through ransomware activities. While their targeting focus has included healthcare organizations due to the sector's sensitive data and potential for high-ransom demands, the group’s broader targeting patterns remain unclear. Their victims appear to be selected based on ease of access rather than specific geopolitical or industry-related factors. The use of 'name and shame' tactics indicates a sophisticated understanding of victim psychology and pressure points.

Enhanced Description

GOLD BURLAP is a cybercriminal organization specializing in the development and operation of the Pysa ransomware. This ransomware is cross-platform, with known versions developed using C++ and Python. As of December 2020, approximately 50 organizations across various industries were reported to have fallen victim to Pysa attacks. The group's primary motivation appears to be financial gain, achieved through the encryption of victims' data and subsequent demands for payment in exchange for decryption keys or files. The operators behind GOLD BURLAP employ 'name and shame' tactics to increase pressure on targeted organizations, often publicly naming uncooperative victims and sharing stolen data to further coerce payments. This approach is particularly concerning for healthcare organizations, which may face additional risks to patient trust and data privacy. The lack of Pysa advertisements on underground forums suggests that the group operates independently rather than as a RaaS offering, implying a more centralized and controlled operation.

Key Capabilities

  • Development and deployment of Pysa ransomware
  • 'Name and shame' extortion tactics
  • Encryption of sensitive data
  • Cross-platform ransomware capabilities

MITRE ATT&CK Tactics

Initial Access
Credential Access
Exfiltration
Data Destruction

ATT&CK Techniques

T1566.002
T1005.001
T1040.004

Software / Tooling

Pysa (Mespinoza) ransomware

Campaigns & Victims

GOLD BURLAP's campaigns typically involve targeted attacks against healthcare organizations, leveraging phishing or remote access vectors to deploy Pysa. The group operates with a moderate operational tempo, focusing on stealth and persistence to avoid detection. Notable past operations include the December 2020 wave of attacks affecting healthcare entities. Campaigns often involve the encryption of critical systems followed by the publication of victim data to maximize pressure on organizations. Despite their relative lack of visibility in underground forums, the group’s focus on a specific geographic or sectoral targeting strategy remains underdetailed in available intelligence.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Encrypted files with .pysa extensions
  • Network traffic related to Pysa's command-and-control infrastructure
  • Presence of Pysa malware indicators on compromised systems

Recommended Actions

  • Implement multi-factor authentication for RDP and other remote access services
  • Conduct regular patch management and system updates to prevent known vulnerabilities from being exploited
  • Train employees to recognize phishing attempts and suspicious emails
  • Encrypt sensitive data with strong encryption standards and maintain offline backups
  • Develop and implement incident response plans specific to ransomware attacks

Suggested Tags

Ransomware
Financially motivated
Healthcare sector
Cybercriminal group

Confidence Assessment

The available intelligence on GOLD BURLAP is limited, particularly in detailing their initial access methods or specific tradecraft. While the existence of Pysa ransomware and related victim data is well-documented, gaps remain in understanding their full suite of tools, operational strategies beyond healthcare targeting, and long-term goals. The group's lack of visibility on underground forums adds to the uncertainty surrounding their true capabilities and potential evolution.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Financially motivated
Healthcare sector
Cybercriminal group

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.